Izenpe: intermediate certificates not revoked within BR time period
This case is an incident report from Izenpe about four intermediate CA certificates that were not listed in audit reports and were not revoked within the BR time period. Izenpe said it became aware of the issue by reviewing CCADB ALV results and comparing them with clarifications from Kathleen, after which it determined that the SHA1 subCA fingerprints were not included in the audit report. Izenpe initially revoked 3 of the 7 intermediate certificates on 2019-11-22, and explained that it did not revoke the remaining 4 at that time due to the impact revocation would generate because those subCAs issue subscriber certificates used by citizens and entities. Ryan Sleevi clarified expectations on mozilla.dev.security.policy, and Izenpe created this bug as an incident report for the 4 intermediates that were not revoked within the BR time period. Izenpe later reported that all pending subCAs were revoked on 2019-11-29. In follow-up, Izenpe described PKI restructuring to reduce TLS-related disruption and stated that it put a new web certificate management application into production on 2020-02-06; the thread indicates remediation was completed and the affected certificates were revoked.
- Izenpe reported that 7 intermediate certificates were not listed in audit reports and intended to revoke them.
- Izenpe revoked 3 of the 7 intermediate certificates.
- Izenpe revoked the remaining 4 pending intermediate subCAs.
- Izenpe put a new application to manage web certificates into production.
- Izenpe S.A. — Opened the incident report describing four intermediate certificates not listed in audit reports and not revoked within the BR time period, and explained why revocation of the remaining four was initially delayed.
- Izenpe S.A. — Reported that all pending subCAs had been revoked and listed the four affected intermediates with crt.sh links.
- Community commenter — Asked how Izenpe would prevent future revocation delays and what PKI/procedural changes were made to minimize disruption.
- Izenpe S.A. — Described restructuring of TLS PKI to reduce risk and development of a new web application to automate verification and manage TLS certificates.
- Community commenter — Asked whether Izenpe was still on track to have the new system in place by end of month.
- Izenpe S.A. — Stated the new system would be put into production by 2020-01-29 and that the bug would be updated after it was running.
- Izenpe S.A. — Reported that the new application to manage web certificates was put into production.
- Community commenter — Indicated remediation steps were completed, including that the affected certificates were revoked and that Izenpe restructured its TLS PKI to prevent further delays.
- Fastly representative — Commented that it appeared all questions were answered and remediation was complete.